CFO Daily · Friday, October 2 · 6 min
CFO Daily · Friday, October 2, 2026
Transcript
Koko: The sharpest thing on my screen today: a piece arguing that once AI touches a financial number, it's inside ICFR. Full stop. Not an IT control, a SOX control.
Sam: Which means agent logins need the same auditability as a journal entry. Most controllers haven't scoped that conversation yet.
Koko: Same day, The Accounting Podcast flags EY cutting audit deficiencies from twenty eight percent to under five percent with AI-assisted review. That's the proof it can work.
Sam: And accounting pay is rising for AI-exposed roles, not falling, per that same episode. Fewer staff, more agents, higher comp for whoever's left reviewing them.
Koko: Then there's Bain's number: AI infrastructure spend is running way ahead of software revenue industry-wide.
Sam: So the through-line is: governance catches up or it doesn't, but the spend and the risk are already inside your control perimeter whether you've mapped it or not.
Koko: Let's actually sit in the PiTech argument. Any AI calculation or recommendation feeding a number on the financials is in ICFR scope. Auditors will ask two things: what human control wraps the AI, and can you reconstruct its reasoning from logs, not memory.
Sam: That second part is the killer. Most teams can tell you what the model output. Almost none can tell you why, after the fact, from an audit trail.
Koko: And agentic systems run under non-human identities. That's a new category for access control, not a tweak to an existing one.
Sam: Here's my pushback though — is this actually new risk, or just an old risk finally getting named? Spreadsheet macros and RPA bots have been quietly touching the financials for years with thin logging.
Koko: Fair, but the scale and the autonomy are different. An agent can change its own approach step to step. A macro doesn't improvise.
Sam: Okay, that I'll grant. Improvisation inside a financial control is exactly what an auditor can't sign off on without a log.
Koko: So the action is concrete: inventory every AI touchpoint that influences a number before your next external audit cycle. The PiTech piece calls undocumented AI use in reporting a material control gap, not a nice-to-have fix.
Sam: Controllers, that's your Monday. Walk your close process and ask where AI sits, even the tools nobody labeled as AI.
Koko: Bain's Global Technology Report puts a number on something we've been circling: AI infrastructure spend is projected past one and a half trillion dollars annually by twenty thirty one, and that requires roughly six trillion in total revenue to sustain.
Sam: And productivity gains and subscriptions don't get anywhere near that. Per Bain, there's a four trillion dollar gap that has to come from categories that barely exist yet — autonomous vehicles, robotics, drug discovery.
Koko: Which is exactly why Gartner's forward-deployed-engineer number matters this week too. Seventy percent of vendor-led FDE engagements are expected to be abandoned by twenty twenty eight.
Sam: Vendors are charging up to two hundred thousand dollars a quarter per use case for implementation help, and there are only about two thousand active FDEs against four times that demand.
Koko: So if you're signing an AI vendor deal with heavy implementation services attached, that's a cost line to interrogate, not a given.
Sam: Tie payment milestones to measured adoption, not deployment headcount. That's the actual negotiating lever here.
Koko: Where we might split: I read the Bain gap as a sector-level solvency question. You're reading it as a vendor-contract question.
Sam: Both are true, but only one of them is on your desk this quarter. The vendor contract is what your procurement team signs tomorrow.
Koko: Barclays has Claude running across sixteen thousand-plus employees, routing a hundred twenty thousand emails a day in Global Markets. That's operations scale, not a pilot.
Sam: And at the CNBC AI Forum, Wells Fargo said they're tracking token spend and capping employee usage, while OpenAI's Bret Taylor pitched outcomes-based pricing where you pay only when agents deliver results.
Koko: If that pricing model spreads, vendor risk-sharing finally becomes real instead of promised.
Koko: So here's the call. Controller: before next quarter's walkthrough, get an access-and-audit-log review done for every AI agent touching financial data. Not IT logging, SOX-grade logging.
Sam: FP&A: when you're modeling vendor AI spend, build in the Bain gap as a scenario, not a footnote. Unit economics before you lock a multi-year compute contract.
Koko: And audit committee: ask for the AI touchpoint inventory directly. If nobody's built one, that's the finding, right there, before the external auditor finds it for you.
Sam: Treasury and procurement, same week: any FDE-heavy vendor proposal gets payment milestones tied to adoption, not headcount. Gartner's seventy percent abandonment number is your leverage.
Koko: That's the brief. Full write-up's at koko knows dot A I.
Sam: Question worth watching: when the first company gets an audit finding specifically citing unauditable AI agent logic, does that become the forcing event everyone else needed?